SB2017092808 - Security restrictions bypass in Siemens products



SB2017092808 - Security restrictions bypass in Siemens products

Published: October 4, 2017

Security Bulletin ID SB2017092808
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security restrictions bypass (CVE-ID: CVE-2017-12736)

The vulnerability allows a adjacent attacker to bypass security restrictions on the target system.

The weakness exists due to improper access controls in the RCDP implementation that is used by Siemens Ruggedcom ROS-based devices and Siemens Scalance X switch models. An adjacent attacker on the same collision or broadcast domain as the target system can bypass security restrictions, gain unauthorized access and perform administrative actions.

Remediation

Install update from vendor's website.